Who is responsible?
The data controller is SenLab AI (Daya Sylla).
- Website: www.senlab-ai.org
- Email: contact@senlab-ai.org
- Written correspondence: France (via the email above)
- Form: Contact page
What data, why, and for how long
We only collect what is needed to reply, secure the site and, if you accept, measure audience.
We never sell your personal data.
Contact form
When you write to us, we process:
- Name
- Email address
- Subject
- Message content
- Page URL and source identifier
- Browser technical data (security, anti-spam). The visitor IP may be seen transiently by the server and is not stored with the message in the database.
The form also includes bot protection (Cloudflare Turnstile). This data is used only to handle your request and contact you back.
Legal basis: legitimate interest, and consent when you accept the policy before sending.
Retention: 3 years after the last exchange, then deletion or anonymisation.
Assistant
The text of your questions is sent to a Google model (via our API) to generate a reply. The conversation history is kept in your browser. We do not use these exchanges for advertising or commercial profiling.
Browsing and cookies
Technical data (theme, consent, interface preferences) stays in your browser. Aggregated audience data is collected only after your consent — see Cookies.
Retention periods
| Data type | Maximum period |
|---|---|
| Contact form | 3 years after last exchange |
| Audience data (if consent) | 13 months |
| Security logs | 12 months |
Recipients, hosting and transfers
Your data is accessible only to the people and providers who need it:
- The SenLab AI team
- Resend (sending contact-form emails)
- Google Cloud (Cloud Run hosting)
- Cloudflare (form bot protection)
- Google (assistant replies)
- Audience and analytics tools, only after consent: Google Analytics, PostHog (EU), and Microsoft Clarity (session recording / navigation replay)
These providers are bound by confidentiality and security obligations. The site is hosted on Google Cloud Run. Despite our measures (HTTPS, encrypted communications, access control and monitoring, backups), no system is completely invulnerable.
Transfers outside the European Union
Some cloud or analytics services may involve a transfer outside the EU. Where that happens, we rely on GDPR safeguards (standard contractual clauses; EU hosting for PostHog).
Cookies and similar technologies
You can change your choice here at any time. The same choice is offered in the banner shown on your first visit. Consent expires after 13 months: the banner is then shown again.
Strictly necessary cookies
Required for the site to work: theme preference, cookie consent, and a few interface settings (assistant panel, layout). The language is in the URL (/fr/, /en/), not in a cookie. They do not require consent.
Optional cookies
Audience measurement (Google Analytics, PostHog) and session recording (Microsoft Clarity) — only after your consent. You can refuse them without losing access to the pages.
Your rights
Under the GDPR, you may at any time:
- Access — know what data we hold and obtain a copy
- Rectification — correct inaccurate information
- Erasure — request deletion, within the limits of the law
- Restriction — ask us to freeze processing temporarily
- Objection — object to processing based on legitimate interest
- Portability — receive the data you provided, in a common format
- Withdraw consent — for optional cookies, via the manager above or the banner
To exercise your rights: contact@senlab-ai.org or the contact form. We reply within one month.
If you believe your rights are not being respected, you may lodge a complaint with the CNIL: www.cnil.fr.
Updates
This policy may change to reflect a legal, technical or organisational update. The date at the top of the page is then revised. By continuing to use the site after an update, you are informed of the version in force.